VORANT. Threat Intelligence Sign in Get the full feed

Qilin ransomware claims Textile City victim

high threat manufacturing

Qilin ransomware gang listed 'Textile City' as a victim on its leak site, with limited compromise details disclosed.

This entry is a ransomware victim listing sourced from ransomware.live, tracking a claim by the Qilin ransomware group against an organization referred to as 'Textile City'. The listing indicates a small number of compromised employee credentials (1 employee, 8 third-party employee credentials) and 4 external attack surface findings, likely derived from infostealer log correlation (the article references Hudson Rock's infostealer-to-ransomware intelligence tooling as a sponsor). No further technical details, TTPs, ransom demands, or data samples are provided in this record.

Defenders in the textile/manufacturing or related supply-chain sectors should treat this as a low-detail indicator that Qilin activity is ongoing and that credential exposure via infostealers remains a common precursor to ransomware intrusions. Organizations should monitor for employee and third-party credential leaks, review external attack surface exposure, and ensure infostealer malware detection and credential hygiene practices are in place, particularly around VPN, RDP, and other remote access services often abused by Qilin affiliates.

Mentioned in this report

Threat actors qilin
Malware Qilin

Source reporting: https://www.ransomware.live/id/VGV4dGlsZSBDaXR5QHFpbGlu

This is the public brief

Subscribers see the full picture: extracted IOCs, ready-to-deploy detections (Sigma, Splunk, KQL, Elastic, YARA, Suricata), the entity graph, TAXII 2.1 feed and real-time alerts matched to your sectors.

Start free